Privacy Policy
Display Units: Wholesale B2B · Last updated: 12 August 2026
Display Units: Wholesale B2B is provided by Skylight Media ("we", "us"). Contact: apps@skylightmedia.co.uk
Who this covers
Two groups:
- Merchants — Shopify store owners who install the app
- Buyers — trade customers who fill and order a display through a merchant's store
For any buyer data, the merchant is the data controller and we act as their processor. We handle buyer data only on the merchant's behalf and only to provide the app. In practice the app stores no buyer-identifying data in its records — see "What we process about buyers" below.
What we collect from merchants
- Shopify store domain
- A session record holding the store domain, an access token allowing the app to call
Shopify's API on the store's behalf, and the permissions granted. The app requests only
three: read access to products, read access to inventory levels (so the configurator can
hide sold-out products and cap quantities — this is stock data, not customer data), and
permission to run its cart price function (
read_products,read_inventory,write_cart_transforms). The app uses store-level ("offline") tokens only, so no individual staff member's name, email address or account is recorded - App configuration: package definitions, display type names, and pack size / stock buffer settings
- Subscription status for the store — which plan is active and whether a trial is running
Subscription and payment
The app is paid for by subscription. Billing is handled entirely by Shopify App Pricing (the plan is configured in Shopify's Partner Dashboard and Shopify hosts the plan-selection page): the merchant approves the charge inside their Shopify admin, Shopify takes payment through the merchant's existing Shopify account, and it appears on their Shopify invoice.
We never see or store payment card details, bank details or billing addresses. The app reads only whether a store has an active subscription and which plan, in order to decide whether to let the admin through.
Support correspondence
The app's "Need support?" link opens a message in the merchant's own email program, addressed to us, with their store domain filled in. Nothing is sent through the app itself, and nothing is sent until the merchant presses send in their own email program. Once they do, we aim to respond within 48 hours and hold that correspondence in our mailbox for 30 days.
What we process about buyers
The app stores no buyer-identifying data in its records.
When a trade buyer uses the on-store configurator to fill a display, the app records an anonymous build: which package it is, which products were chosen and in what quantity, and a random build identifier. This lets Shopify charge the single fixed package price for the finished display, and lets the buyer return later to edit their selection. A build is not linked in our records to the buyer's name, email, customer account, company or order — it carries nothing that identifies a person.
For completeness: when a signed-in buyer opens the configurator, Shopify includes that buyer's Shopify customer ID in the request it sends the app. The app does not read, use or store this ID — it is never recorded against a build — though it may appear transiently in the app's server request logs. We request no other buyer data from Shopify: no names, email addresses, phone numbers, postal addresses, customer accounts, companies or orders. We do not collect payment details; payments are handled by Shopify.
Why we process it
- To operate the on-store display configurator
- To apply the single fixed package price to a finished display, using Shopify's Cart Transform
That is the whole of it. We run no analytics, we do not tag or read orders, we do not use buyer data for marketing, we do not sell or share it, we build no profiles, and we make no automated decisions about individuals.
Tracking, cookies and browser storage
The app sets no tracking cookies and runs no analytics scripts on storefronts. The buyer-facing configurator uses JavaScript only to operate the interface — counting selections and updating the display. We do not observe buyers who do not build a display.
It does use two pieces of storage on the buyer's own device, both strictly necessary to provide the feature the buyer has asked for, and neither used to track anyone:
- Session storage holds the display a buyer is part-way through building, so that reloading the page or stepping away does not lose their work. It never leaves the browser, is cleared once the display is added to the basket, and is discarded by the browser when the tab closes.
- Basket line properties record which display a basket line belongs to, so the fixed package price can be applied and so the buyer can go back and edit that display. These live in the merchant's Shopify basket, not with us.
Because both are strictly necessary for a service the buyer has actively requested, they fall within the exemption in the UK Privacy and Electronic Communications Regulations and do not require a consent banner. We mention them because they are storage on a device, and we would rather be explicit than technically silent.
Where data is held
In a PostgreSQL database hosted by Neon, and on application servers hosted by Fly.io, both in the United Kingdom (London). Data is encrypted in transit and at rest.
Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Neon | Database hosting | United Kingdom (London) |
| Fly.io | Application hosting | United Kingdom (London) |
| Shopify | The merchant's own platform, where the app runs | — |
How long we keep it
- While installed — for as long as the merchant uses the app
- On uninstall — Shopify notifies us and we delete the store's data, normally within 48 hours and in all cases within 30 days
- On a buyer erasure request — Shopify may forward a customer redaction request. Because we store no buyer-identifying data in our records, there is nothing to erase; we record that the request was received and confirm
Buyer rights
Because the app stores no buyer-identifying data in our records, we hold nothing to return in response to an access request and nothing to erase on a redaction request. Buyers should still contact the merchant they ordered from — the merchant is the controller and owns that relationship. Shopify provides merchants with tools to request or erase customer data, and we act on those requests automatically.
Rights under UK and EU data protection law include access, rectification, erasure, restriction, portability and objection.
Security
- Encryption in transit (TLS) and at rest
- Separate development and production databases; development never uses real merchant data
- Access to production limited to named personnel with two-factor authentication
- Administrative and compliance events are logged
- A documented incident response procedure, including notification of merchants and the ICO within 72 hours of becoming aware of a personal data breach where required
Changes
We will update this policy when the app's data handling changes, and update the date above. Material changes will be communicated to merchants.
Contact: apps@skylightmedia.co.uk
If you are in the UK and unsatisfied with our response, you may complain to the Information Commissioner's Office (ico.org.uk).